Cyber & AI intelligence
Wasteland.
Briefs indexed2982
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-19652 2026-10-02

CVE-2026-19652: Unauthenticated Admin Takeover in Divi Membership for WordPress

"A critical privilege escalation flaw (CVSS 9.8) in the Divi Membership WordPress plugin, versions up to and including 2.2.0, lets unauthenticated attackers register a new administrator account and log in as that…"

A critical privilege escalation flaw (CVSS 9.8) in the Divi Membership WordPress plugin, versions up to and including 2.2.0, lets unauthenticated attackers register a new administrator account and log in as that account, which gives them full control of the site.

What Is It

CVE-2026-19652 is a privilege escalation vulnerability (CWE-269) in DiviEngine's Divi Membership plugin. The bug is in the dmem_form_submit_handler() function. To decide the role for a new user, the function loops through every WordPress role and calls password_verify() against a bcrypt hash that the attacker supplies in the form_id POST parameter. It does not validate the role or check it against a list of allowed roles.

An attacker can compute a bcrypt hash of the string administrator on their own machine and submit it as form_id. That registers a new account with the administrator role. If the attacker also submits auto_login=on, they are logged in as that administrator in the same request.

The exploit needs a WordPress nonce. However, the nonce appears publicly on any page that shows the Divi Membership registration form, so any unauthenticated visitor can get it.

Why It Matters

This CVE is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) Catalog. The supplied data does not confirm active exploitation, and there is no CISA required action or deadline.

What's Vulnerable

Any site with an affected version that shows the Divi Membership registration form should be treated as exposed.

Patch Status

The NVD record lists versions up to and including 2.2.0 as affected. It does not name a specific fixed release. Administrators should check DiviEngine's changelog for a release that fixes this issue, update when one is available, and audit their sites for administrator accounts they don't recognize. Wordfence published the advisory, and the NVD status is currently "Deferred."

Sources